Thesis · in progress
The Schedule-Access Gap
Why HIPAA's “minimum necessary” doctrine requires time-aware IAM.
The full-length piece is being drafted and will appear here on publication. It argues that the dominant IAM stack — Okta, SailPoint, CyberArk, Microsoft Entra — cannot defensibly enforce HIPAA's minimum-necessary access principle for shift workers, because none of them are aware of when an employee is actually on shift.
The argument runs in three moves:
- Time-based conditional access is not schedule-aware. Okta's 9-to-5 rules are calendar-based, not bound to verified shifts.
- Standing access creates standing risk. 75% of insider security incidents (Ponemon 2024) are non-malicious — employees with access they no longer need.
- The bridge has to be its own platform. No incumbent can ship schedule-aware policies without cannibalizing their core conditional-access licensing — making this a category-creation opportunity.
Want the draft when it's ready?
Walk the demo and the post-call follow-up will include early access.
Walk the demo →